Wordpress I Love It Theme Multiple Vulnerabilities

This host is installed with Wordpress I Love It Theme and is prone to multiple vulnerabilities.
Successful exploitation will allow remote attacker to execute arbitrary HTML or script code in the context of the affected site and disclose some sensitive information. Impact Level: Application
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
Multiple flaws are due to, - Input passed via 'playerID' parameter to '/iloveit/lib/php/assets/player.swf' script is not properly sanitised before being return to the user. - Not properly restrict access to certain files.
Wordpress I Love It Theme version 1.9 and prior
Send a HTTP GET request and check whether it is able to disclose the path or not.